Quick Reference Guide

ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual
B-12 Network Planning for Dual WAN Ports
v1.0, January 2010
VPN Road Warrior: Dual Gateway WAN Ports for Improved Reliability
In the case of the dual WAN ports on the gateway VPN firewall, the remote PC client initiates the
VPN tunnel with the active gateway WAN port (port WAN1 in this example) because the IP
address of the remote PC client is not known in advance. The gateway WAN port must act as a
responder.
The IP addresses of the gateway WAN ports can be either fixed or dynamic, but a fully-qualified
domain name must always be used because the active WAN port could be either WAN1 or WAN2
(i.e., the IP address of the active WAN port is not known in advance).
After a rollover of the gateway WAN port, the previously inactive gateway WAN port becomes the
active port (port WAN2 in this example) and the remote PC client must re-establish the VPN
tunnel. The gateway WAN port must act as the responder.
Figure B-10
Figure B-11